| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-6232 | Regular-expression DoS when parsing TarFile headers | Python Software Foundation | CPython | 中危 | - | 2024-09-03 12:29:00 | Deep Dive |
| CVE-2024-8088 | Infinite loop when iterating over zip archive entry names from zipfile.Path | Python Software Foundation | CPython | 中危 | - | 2024-08-22 18:45:32 | Deep Dive |
| CVE-2024-7592 | Quadratic complexity parsing cookies with backslashes | Python Software Foundation | CPython | 中危 | - | 2024-08-19 19:06:45 | Deep Dive |
| CVE-2024-6923 | Email header injection due to unquoted newlines | Python Software Foundation | CPython | 中危 | - | 2024-08-01 13:40:11 | Deep Dive |
| CVE-2024-3219 | Pure-Python fallback of socket.socketpair() doesn’t authenticate peer connection | Python Software Foundation | CPython | - | - | 2024-07-29 21:54:06 | Deep Dive |
| CVE-2024-5642 | Buffer overread when using an empty list with SSLContext.set_npn_protocols() | Python Software Foundation | CPython | - | - | 2024-06-27 21:05:31 | Deep Dive |
| CVE-2024-0397 | Memory race condition in ssl.SSLContext certificate store methods | Python Software Foundation | CPython | - | - | 2024-06-17 15:09:41 | Deep Dive |
| CVE-2024-4032 | Incorrect IPv4 and IPv6 private ranges | Python Software Foundation | CPython | - | - | 2024-06-17 15:05:59 | Deep Dive |
| CVE-2024-4030 | tempfile.mkdtemp() may be readable and writeable by all users on Windows | Python Software Foundation | CPython | - | - | 2024-05-07 21:02:55 | Deep Dive |
| CVE-2023-6597 | Python 安全漏洞 | Python Software Foundation | CPython | High | 7.8 | 2024-03-19 15:44:29 | Deep Dive |
| CVE-2024-0450 | Quoted zip-bomb protection for zipfile | Python Software Foundation | CPython | Medium | 6.2 | 2024-03-19 15:12:08 | Deep Dive |
| CVE-2023-6507 | Groups not dropped before running subprocess when using empty 'extra_groups' parameter | Python Software Foundation | CPython | Medium | 6.1 | 2023-12-08 18:20:50 | Deep Dive |
| CVE-2021-23336 | Web Cache Poisoning | - | python/cpython | Medium | 5.9 | 2021-02-15 12:15:21 | Deep Dive |